Executive brief
Windows Credential Guard is a Windows system component that protects credentials stored on a device. A heap-based buffer overflow vulnerability in this component allows an authorized local attacker to gain elevated privileges and potentially compromise system security. This could enable attackers with local access to bypass security controls and gain administrative access to the system.
Technical details
A heap-based buffer overflow exists in Windows Credential Guard that can be triggered by an authorized attacker with local system access. The vulnerability allows an attacker to overflow a heap buffer, potentially corrupting heap memory and achieving arbitrary code execution with elevated privileges. Exploitation requires prior authorization on the system and local network access. Successful exploitation could result in privilege escalation from a lower-privileged account to SYSTEM or administrator level. Microsoft has issued security updates to address this vulnerability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed